SB2018090614 - Privilege escalation in Cisco Webex Meetings Client



SB2018090614 - Privilege escalation in Cisco Webex Meetings Client

Published: September 6, 2018

Security Bulletin ID SB2018090614
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Privilege escalation (CVE-ID: CVE-2018-0422)

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The vulnerability exists in the folder permissions due to folder permissions that grant a user the permission to read, write, and execute files in the Webex folders. A local attacker can write malicious files to the Webex client directory, affecting all other users of the targeted device and execute commands with elevated privileges.


Remediation

Install update from vendor's website.